ZDI-CAN-17203: (Pwn2Own) Unified Automation OPC UA C++ Infinite Loop Denial-of-Service Vulnerability
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Unified Automation OPC UA C++ Demo Server. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of certificates. A crafted certificate can force the server into an infinite loop. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-17203?
The severity of ZDI-CAN-17203 is classified as high due to its potential to cause denial-of-service conditions.
How do I fix ZDI-CAN-17203?
To fix ZDI-CAN-17203, it's recommended to update the Unified Automation OPC UA C++ Demo Server to the latest version provided by the vendor.
Can ZDI-CAN-17203 be exploited remotely?
Yes, ZDI-CAN-17203 can be exploited remotely by unauthorized attackers.
Is authentication required to exploit ZDI-CAN-17203?
No, authentication is not required to exploit the vulnerability identified as ZDI-CAN-17203.
What specific flaw does ZDI-CAN-17203 address?
ZDI-CAN-17203 addresses a flaw in the handling of certificates within the Unified Automation OPC UA C++ Demo Server.